Executive brief
Netdata, a real-time infrastructure monitoring tool, contained a security flaw in its SVG image generation service. An attacker could send a specially crafted link to a user; if clicked, the link would execute malicious code within the user's web browser under the context of the Netdata application. This could allow an attacker to perform unauthorized actions or steal sensitive session information from the monitoring dashboard.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in Netdata versions prior to 2.3.1. The 'love' query parameter in the api/v2/ilove.svg and api/v3/ilove.svg endpoints is reflected verbatim into a generated SVG document's text element without proper HTML or XML escaping. Because these endpoints are served with the 'image/svg+xml' content type and are accessible without authentication (HTTP_ACL_NOCHECK), an attacker can execute arbitrary JavaScript in a victim's browser by inducing them to click a malicious URL. The vulnerability was addressed in version 2.3.1 by completely removing the affected 'ilove' endpoints.
Affected products
- Netdata Netdata before 2.3.1
Timeline
- 2025-03-20: patched: Fix merged into master branch via PR #19919
- 2025-03-24: advisory: Release v2.3.1 published
- 2026-07-02: disclosed: CVE-2025-71385 published to NVD